Skip to content

gemaraproj/gemara

Gemara: GRC Engineering Model for Automated Risk Assessment Go Reference

Pronounced: Juh-MAH-ruh (think 💎)

Gemara is a standardized, machine-readable data model designed to bridge the gap between high-level compliance requirements and low-level technical evidence. By providing a structured schema (powered by CUE), Gemara enables automated risk assessment, consistent reporting, and interoperability across the security toolchain.

Resources

  1. View the model and supporting resources at gemara.openssf.org
  2. Find schemas in this repository, or in the CUE central registry.
  • Use the schemas directly with cue for validating Gemara data payloads against the schemas and more.
  1. Use the Go SDK to integrate Gemara schemas into your automated tools
  • github.com/gemaraproj/go-gemara and consult our go docs

Projects and tooling using Gemara

Some Gemara use cases include:

Contributing

We're so glad you asked - see CONTRIBUTING.md and if you have any questions or feedback head over to the OpenSSF Slack in #gemara

You can also join the biweekly meeting on alternate Thursdays.
See Gemara Bi-Weekly Meeting on the OpenSSF calendar for details.

About

Minimizing rework for governance activities.

Resources

License

Code of conduct

Contributing

Security policy

Stars

Watchers

Forks

Contributors 12